Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Imagemagick HIGH 8.8
CVE-2016-4563

The TraceStrokePolygon function in MagickCore/draw.c in ImageMagick before 6.9.4-0 and 7.x before 7.0.1-2 mishandles the relationship between the Bez…

Fix: after 6.9.3-0
Fix from $1,950 2016-06-04
Imagemagick HIGH 8.8
CVE-2016-4562

The DrawDashPolygon function in MagickCore/draw.c in ImageMagick before 6.9.4-0 and 7.x before 7.0.1-2 mishandles calculations of certain vertices in…

Fix: after 6.9.3-0
Fix from $1,950 2016-06-04
Ubuntu Linux MEDIUM 6.2
CVE-2016-4804

The read_boot function in boot.c in dosfstools before 4.0 allows attackers to cause a denial of service (crash) via a crafted filesystem, which trigg…

Fix: after 3.0.28
Fix from $1,600 2016-06-03
Ubuntu Linux MEDIUM 6.0
CVE-2016-4454

The vmsvga_fifo_read_raw function in hw/display/vmware_vga.c in QEMU allows local guest OS administrators to obtain sensitive host memory information…

Fix: after 2.6.0
Fix from $1,600 2016-06-01
Fedora HIGH 7.5
CVE-2016-3075EPSS 8%

Stack-based buffer overflow in the nss_dns implementation of the getnetbyname function in GNU C Library (aka glibc) before 2.24 allows context-depend…

Fix: after 2.23
Fix from $1,950 2016-06-01
Fedora HIGH 7.5
CVE-2016-1234EPSS 5%

Stack-based buffer overflow in the glob implementation in GNU C Library (aka glibc) before 2.24, when GLOB_ALTDIRFUNC is used, allows context-depende…

Fix: 2.24+
Fix from $1,950 2016-06-01
Mate 8 Firmware HIGH 7.8
CVE-2016-3681

Buffer overflow in the Wi-Fi driver in Huawei Mate 8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and…

Mitigation only
Fix from $1,950 2016-05-26
Mate 8 Firmware HIGH 7.8
CVE-2016-3680

Buffer overflow in the Wi-Fi driver in Huawei Mate 8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and…

Mitigation only
Fix from $1,950 2016-05-26
Firefox CRITICAL 9.8
CVE-2016-0718EPSS 13%

Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, whic…

Fix: 2.7.15 / 3.3.7+
Fix from $2,300 2016-05-26
Adaptive Security Appliance Software MEDIUM 6.5
CVE-2016-1385

The XML parser in Cisco Adaptive Security Appliance (ASA) Software through 9.5.2 allows remote authenticated users to cause a denial of service (inst…

Mitigation only
Fix from $1,600 2016-05-26
FreeBSD HIGH 7.8
CVE-2016-1886

Integer signedness error in the genkbd_commonioctl function in sys/dev/kbd/kbd.c in FreeBSD 9.3 before p42, 10.1 before p34, 10.2 before p17, and 10.…

Patch available
Fix from $1,950 2016-05-25
Satellite MEDIUM 5.6
CVE-2016-0264

Buffer overflow in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25)…

Mitigation only
Fix from $1,600 2016-05-24
Usg9500 Firmware HIGH 7.5
CVE-2016-4577

Buffer overflow in the Smart DNS functionality in the Huawei NGFW Module and Secospace USG6300, USG6500, USG6600, and USG9500 firewalls with software…

Mitigation only
Fix from $1,950 2016-05-23
Nip6300 Firmware CRITICAL 9.8
CVE-2016-4576

Buffer overflow in the Application Specific Packet Filtering (ASPF) functionality in the Huawei IPS Module, NGFW Module, NIP6300, NIP6600, Secospace …

Mitigation only
Fix from $2,300 2016-05-23
Linux Kernel HIGH 7.8
CVE-2016-4568

drivers/media/v4l2-core/videobuf2-v4l2.c in the Linux kernel before 4.5.3 allows local users to cause a denial of service (kernel memory write operat…

Fix: 4.4.9 / 4.5.3+
Fix from $1,950 2016-05-23
PHP CRITICAL 9.8
CVE-2016-4544EPSS 7%

The exif_process_TIFF_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate TIFF star…

Fix: 5.5.35 / 5.6.21+
Fix from $2,300 2016-05-22
PHP CRITICAL 9.8
CVE-2016-4543EPSS 12%

The exif_process_IFD_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate IFD sizes,…

Fix: after 7.5.5.6
Fix from $2,300 2016-05-22
Identity Services Engine Software HIGH 7.5
CVE-2016-1402

The Active Directory (AD) integration component in Cisco Identity Service Engine (ISE) before 1.2.0.899 patch 7, when AD group-membership authorizati…

Mitigation only
Fix from $1,950 2016-05-21
Ubuntu Linux MEDIUM 6.0
CVE-2016-4441

The get_cmd function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) support in QEMU does not properly check DMA length, which allows local …

Fix: after 2.6.0
Fix from $1,600 2016-05-20
Ubuntu Linux MEDIUM 6.7
CVE-2016-4439

The esp_reg_write function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) support in QEMU does not properly check command buffer length, wh…

Fix: after 2.6.0
Fix from $1,600 2016-05-20
PHP CRITICAL 9.8
CVE-2016-4073EPSS 7%

Multiple integer overflows in the mbfl_strcut function in ext/mbstring/libmbfl/mbfl/mbfilter.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x bef…

Fix: after 10.11.3
Fix from $2,300 2016-05-20
Safari HIGH 8.8
CVE-2016-1859

The WebKit Canvas implementation in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1 allows remote attackers to execute arbitrary c…

Fix: 2.12.1 / 9.1.1+
Fix from $1,950 2016-05-20
Safari HIGH 8.8
CVE-2016-1857

WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a d…

Fix: 2.12.3 / 9.1.1+
Fix from $1,950 2016-05-20
Safari HIGH 8.8
CVE-2016-1856

WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a d…

Fix: 2.12.1 / 9.1.1+
Fix from $1,950 2016-05-20
Safari HIGH 8.8
CVE-2016-1854

WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a d…

Fix: 2.12.1 / 9.1.1+
Fix from $1,950 2016-05-20
Safari HIGH 8.8
CVE-2016-1855

WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a d…

Fix: 9.1.1 / 9.2.1+
Fix from $1,950 2016-05-20
Mac Os X HIGH 7.8
CVE-2016-1850

SceneKit in Apple OS X before 10.11.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafte…

Fix: after 10.11.4
Fix from $1,950 2016-05-20
Mac Os X HIGH 7.8
CVE-2016-1848EPSS 5%

QuickTime in Apple OS X before 10.11.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craft…

Fix: after 10.11.4
Fix from $1,950 2016-05-20
Iphone Os HIGH 8.8
CVE-2016-1847

OpenGL, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbit…

Fix: 2.2.1 / 9.2.1+
Fix from $1,950 2016-05-20
Mac Os X HIGH 7.8
CVE-2016-1846

The nvCommandQueue::GetHandleIndex method in the NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 allows attackers to execute arbitrary…

Fix: after 10.11.4
Fix from $1,950 2016-05-20